<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Move firewall to new Panorama in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539831#M110747</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate it.&amp;nbsp; &amp;nbsp;If I take care of all the shared objects up front, to make sure they match on old and new panorama , do I still do a partial import or can I just do a full import at that point, since they'll be going into their own DG?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I read through the link you posted about the partial import, but it's not fully clear in my brain how I'd do that.&amp;nbsp; &amp;nbsp;I'm also a little worried about the HA firewalls that need to be added to the new Pano, since even though they are managed by the old Panorama, all of their HA settings are currently locally configured.&amp;nbsp; &amp;nbsp;When I import those FWs into my panorama, I think that config will come too and potentially break&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I eventually will want to make use of template variables and have fewer templates.&amp;nbsp; Create some templates for common settings and use template stacks but that can be done as a different phase.&amp;nbsp; &amp;nbsp;For now, I'm okay with having multiple templates, I'm more bothered by multiple device groups.&amp;nbsp; It's easy to clone rules from 1 DG to another, but it's extra effort &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 23 Apr 2023 18:06:56 GMT</pubDate>
    <dc:creator>securehops</dc:creator>
    <dc:date>2023-04-23T18:06:56Z</dc:date>
    <item>
      <title>Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539747#M110724</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We currently have 2 Panoramas (virtual) managing different firewalls..&amp;nbsp; We'd like to move all firewalls to 1 pano, so we can retire the other one.&amp;nbsp; &amp;nbsp;What's the best/safest way to accomplish that?&amp;nbsp; Is there a way to avoid having duplicate objects while migrating or would it be a cleanup effort after the fact.&amp;nbsp; &amp;nbsp;It's a mix of standalone firewalls and HA (active/passive) firewalls.&amp;nbsp; &amp;nbsp;These are all in production, so concerned about downtime.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know there is a process to import standalone firewalls into panorama, but these firewalls are already managed by pano.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 21:53:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539747#M110724</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2023-04-21T21:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539748#M110725</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a link to a similar thread answered by our CE&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;. As far as duplicating objects, you can import them into their own device groups and not have them at the shared level.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 22:12:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539748#M110725</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-04-21T22:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539767#M110727</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks but I don't see a link.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as the duplicates, sure can do that but then you have a device group for every firewall you bring in and then won't have a consistent security policy.&amp;nbsp; Many of the firewalls are all currently in the same device group to have a consistent policy&lt;/P&gt;</description>
      <pubDate>Sat, 22 Apr 2023 01:41:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539767#M110727</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2023-04-22T01:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539786#M110734</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt; 's point was that keeping them in their own device groups avoids duplicate errors when you import the configuration into Panorama.&amp;nbsp; Before we discuss duplicates, let's talk about how to get the configurations from the old Panorama to the new one.&amp;nbsp; I can think of 2 ways:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If you have Expedition, you can use it to merge the configurations and clean up duplicates.&amp;nbsp; Then you can import the configuration into the new Panorama.&lt;/LI&gt;
&lt;LI&gt;If you do not have Expedition, you can use the "load config partial mode merge" command to import the device group and templates into the new Panorama.&amp;nbsp; If you have duplicate names in the Shared device group, you will get errors.&amp;nbsp; If the duplicates also have the same value, you do not need to fix anything.&amp;nbsp; They are already there.&amp;nbsp; If they have the same name and a different value (which seems doubtful), you will need to fix it.&amp;nbsp; Items with duplicate values will need to be cleaned up afterwards.&amp;nbsp; Duplicate rules will need to be cleaned up afterwards.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbLCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbLCAS&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Any time that you import configurations into Panorama as opposed to building them from scratch, you will need to do some cleanup/restructuring.&amp;nbsp; Thankfully, the Move button on the bottom of Policies and Objects makes that easier.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We can discuss either option in more detail on this thread.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 22 Apr 2023 10:35:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539786#M110734</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-22T10:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539793#M110739</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Agree completely on&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;point.&amp;nbsp; This was my original thought too but since I'll be bringing a number of firewalls, for each of them to have their own device group (policy set) decided that would not be ideal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do have some follow up questions but wanted to provide some info on the current environment&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the source side (panorama to be retired/fws to be imported)&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;All firewalls that we want to migrate to our main Panorama are currently being managed by the soon-to-be retired Panorama but may or may not have some local configuration&lt;/LI&gt;
&lt;LI&gt;Multiple templates.&amp;nbsp; A majority of the firewalls are in a single template, but some are in their own templates&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;2&lt;/STRONG&gt; device groups -&amp;nbsp; All but a pair of HA fws are part of a single device group.&amp;nbsp; The other HA pair has its own device group&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;All objects in that Panorama are in location shared, none are device group specific&lt;/LI&gt;
&lt;LI&gt;For internal/external traffic the zone names are internal/external (additional zones exist that don't exist on other panorama)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the destination side (main Panorama)&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Multiple templates.&amp;nbsp; A majority of the firewalls are in a single template, but some are in their own template&lt;/LI&gt;
&lt;LI&gt;Multiple device groups -&amp;nbsp; Majority of the firewalls belong to a specific device group and this is the device group I'd like to bring these firewalls into&lt;/LI&gt;
&lt;LI&gt;98% of objects&amp;nbsp; are in location shared&lt;/LI&gt;
&lt;LI&gt;For internal/external traffic the zone names are trust/untrust&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My questions are&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;To move this over, would I have to first remove the firewalls from their current Panorama and make their entire config local (and temporarily unmanaged).&amp;nbsp; If so, how does this impact the firewalls in HA pairs?&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;Since it's Panorama to Panorama, is it done all at one time, or can it be phased and move firewall by firewall over?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I currently do not have expedition, would you recommend using it for this scenario?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 22 Apr 2023 17:36:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539793#M110739</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2023-04-22T17:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539794#M110740</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the excellent info.&amp;nbsp; Let me answer your 2 questions 1st:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You do not have to move all of the config locally.&amp;nbsp; You can import the device configuration (including Shared) and templates into the new Panorama using "load config partial mode merge".&amp;nbsp; This would be preferred because moving all the config locally can make it difficult to move partial Network and Device configuration to Panorama.&lt;/LI&gt;
&lt;LI&gt;It can definitely be phased over 1 NGFW at a time.&amp;nbsp; If you are using template variables, make sure you manually configure those after the NGFWs are moved to Panorama.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Expedition makes some things easier, but it does take time to install and learn.&amp;nbsp; Unless you have a LOT of objects, I probably would not.&amp;nbsp; Instead, I would do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;As much as possible, I would change the object names on the old to match the new.&amp;nbsp; Definitely have Automated Commit Recovery enabled before you do this.&amp;nbsp; Make sure the device group and template names are different!&lt;/LI&gt;
&lt;LI&gt;Rename your zones on the old Panorama to match the new.&amp;nbsp; This is tricky.&amp;nbsp; After the rename, create the old zones again in the templates so that the push does not fail on the managed device.&amp;nbsp; After the push is successful, delete the old zones.&lt;/LI&gt;
&lt;LI&gt;Rename your shared objects before the migration.&amp;nbsp; It will be easier to standardize the names before the migration because you can just rename and not have to swap objects inside the policies.&amp;nbsp; Otherwise, Expedition makes the rename/swap easier.&lt;/LI&gt;
&lt;LI&gt;When you migrate a NGFW, aim for a like-for-like configuration.&amp;nbsp; Don't adjust the templates or device groups on the new Panorama until all the devices are moved.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 22 Apr 2023 20:48:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539794#M110740</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-22T20:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539808#M110744</link>
      <description>&lt;P&gt;Well, this is interesting.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/panorama/panorama-interconnect/1-0/panorama-interconnect-admin" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/panorama-interconnect/1-0/panorama-interconnect-admin&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone used Panorama Interconnect?&amp;nbsp; I wonder if &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt; could use it to pull the configs from the old Panorama to the new?&amp;nbsp; I looked through the docs and did not find anything.&amp;nbsp; Once done, you could remove the plugin.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 01:57:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539808#M110744</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-23T01:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539809#M110745</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firstly, thanks for the info on this.&amp;nbsp; It's very helpful not only for me but also for the entire community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the address objects, not a lot, I believe its somewhere between 250 - 300.&amp;nbsp; So that sounds like no real need for Expedition.&amp;nbsp; I've never used it personally, I've only watched the youtube series on it, in the past&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have some follow up questions, based on your reply. I'm a little confused&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;As much as possible, I would change the object names on the old to match the new.&amp;nbsp; Definitely have Automated Commit Recovery enabled before you do this.&amp;nbsp; Make sure the device group and template names are different!&lt;BR /&gt;&lt;STRONG&gt;Just to confirm that I'm understanding what you mean here...are you saying if on old pano, I have an object named "Object-A" with IP of 1.1.1.1 and on new Pano, I have an object named&amp;nbsp; "Object-B" with IP 1.1.1.1,&amp;nbsp; I should rename Object-A to Object-B on the old pano first?&amp;nbsp; &amp;nbsp; Also, are you saying the device group and template names on the old Pano should NOT be the same as they are on the new pano?&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Rename your zones on the old Panorama to match the new.&amp;nbsp; This is tricky.&amp;nbsp; After the rename, create the old zones again in the templates so that the push does not fail on the managed device.&amp;nbsp; After the push is successful, delete the old zones.&lt;BR /&gt;&lt;STRONG&gt;Thanks for confirming this step.&amp;nbsp; This is exactly what I was planning to do.&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Rename your shared objects before the migration.&amp;nbsp; It will be easier to standardize the names before the migration because you can just rename and not have to swap objects inside the policies.&amp;nbsp; Otherwise, Expedition makes the rename/swap easier.&lt;BR /&gt;&lt;STRONG&gt;Not sure I understand this one, is this different from #1 above?&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;When you migrate a NGFW, aim for a like-for-like configuration.&amp;nbsp; Don't adjust the templates or device groups on the new Panorama until all the devices are moved.&lt;BR /&gt;&lt;STRONG&gt;If on the old pano, I have 2 device groups and 4 templates,&amp;nbsp; after the migration, does this mean I'll have 2 additional device groups and 4 additional templates on the new pano?&amp;nbsp; &amp;nbsp;If so, after I migrate the FWs into the new pano, can I then safely move those FWs into the one existing device groups that was already on the new pano ?&amp;nbsp; &amp;nbsp; The goal here is to have all of the firewalls in our current branch office device group.&amp;nbsp; This way all the security policies/decryption/etc policies are consistent.&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the one area I may have some issues is with the custom URL objects.&amp;nbsp; I'm certain there will be objects there with same name but different values.&amp;nbsp; Will look to match them up prior&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit: forgot to add that in the old panorama, no template variables are used.&amp;nbsp; So for the firewalls that belong to a single template,&amp;nbsp; the values&amp;nbsp; (such as interface IP addresses) are configured locally with an override&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 02:42:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539809#M110745</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2023-04-23T02:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539827#M110746</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Just to confirm that I'm understanding what you mean here...are you saying if on old pano, I have an object named "Object-A" with IP of 1.1.1.1 and on new Pano, I have an object named&amp;nbsp; "Object-B" with IP 1.1.1.1,&amp;nbsp; I should rename Object-A to Object-B on the old pano first?&lt;/STRONG&gt;&amp;nbsp; Yes.&amp;nbsp; If you rename them on the old Pano, all the polices will have matching objects on the new Pano.&amp;nbsp; If you wait to do it after the merge, then you have to go through every rule with Object-B and change it to Object-A.&amp;nbsp; That is, of course, if you want all the objects to be consistent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Also, are you saying the device group and template names on the old Pano should NOT be the same as they are on the new pano?&lt;/STRONG&gt;&amp;nbsp; Yes.&amp;nbsp; I would keep them separate initially so that you have a like-for-like migration.&amp;nbsp; In that way you are reducing the number of changes during the maintenance window.&amp;nbsp; The #1 goal is to move the NGFW and everything work. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Not sure I understand this one, is this different from #1 above?&lt;/STRONG&gt;&amp;nbsp; Good catch.&amp;nbsp; It is not different.&amp;nbsp; I was emphasizing that Shared objects are the most important since they will be merged with Shared on the new Pano.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If on the old pano, I have 2 device groups and 4 templates,&amp;nbsp; after the migration, does this mean I'll have 2 additional device groups and 4 additional templates on the new pano?&lt;/STRONG&gt;&amp;nbsp; Yes, for the purpose of a like-for-like migration.&amp;nbsp; We don't want to break anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If so, after I migrate the FWs into the new pano, can I then safely move those FWs into the one existing device groups that was already on the new pano?&lt;/STRONG&gt;&amp;nbsp; Yes.&amp;nbsp; I would standardize device groups and templates after the move.&amp;nbsp; As you know, this will take a lot of work to ensure the configs stay the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The goal here is to have all of the firewalls in our current branch office device group.&amp;nbsp; This way all the security policies/decryption/etc policies are consistent.&lt;/STRONG&gt;&amp;nbsp; Exactly.&amp;nbsp; You could also consider moving templates also so that you can change something once for all devices.&amp;nbsp; I had to install Panorama in my company after I had a few NGFWs setup.&amp;nbsp; It took some time to import the configurations and move things around.&amp;nbsp; It's done now, and very easy to make changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 13:49:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539827#M110746</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-23T13:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539831#M110747</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate it.&amp;nbsp; &amp;nbsp;If I take care of all the shared objects up front, to make sure they match on old and new panorama , do I still do a partial import or can I just do a full import at that point, since they'll be going into their own DG?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I read through the link you posted about the partial import, but it's not fully clear in my brain how I'd do that.&amp;nbsp; &amp;nbsp;I'm also a little worried about the HA firewalls that need to be added to the new Pano, since even though they are managed by the old Panorama, all of their HA settings are currently locally configured.&amp;nbsp; &amp;nbsp;When I import those FWs into my panorama, I think that config will come too and potentially break&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I eventually will want to make use of template variables and have fewer templates.&amp;nbsp; Create some templates for common settings and use template stacks but that can be done as a different phase.&amp;nbsp; &amp;nbsp;For now, I'm okay with having multiple templates, I'm more bothered by multiple device groups.&amp;nbsp; It's easy to clone rules from 1 DG to another, but it's extra effort &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 18:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539831#M110747</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2023-04-23T18:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539832#M110748</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will not import the NGFW configuration into Panorama at all.&amp;nbsp; You export and import the old Pano configuration onto the new Pano.&amp;nbsp; Do not load it.&amp;nbsp; Reference that file in the "load config partial" command.&amp;nbsp; Basically, you will copy just the device group or template configuration from the old to the new.&amp;nbsp; You can use the API Browser to confirm the XPaths (XML Paths).&amp;nbsp; All the local settings will stay local.&amp;nbsp; We can do a phone call or screen share if needed to further explain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Don't forget you can use the Move button on the bottom of Policies to move rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 19:38:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539832#M110748</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-23T19:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539833#M110749</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;, I totally missed that part.&amp;nbsp; So really, by importing the Pano config, it very low risk, since once it's added, then I can just add the NGFW serial number to the new panorama, change IP on NGFW to point to new Pano, add to the template/dg and push.&amp;nbsp; Since it's one-for-one, like you've mentioned, should just work fine.&amp;nbsp; &amp;nbsp;I guess the only consideration is once I start the process, I should move the NGFW's over relatively quickly, otherwise I'll have to manually keep them up to date.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I appreciate the offer for screen share call, might take you up on that.&amp;nbsp; In the meantime, I will work on renaming zones, renaming/cleaning up shared objects on old Pano and add any objects that don't exist to new pano&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should it matter that old Pano is 9.1 and new Pano is 10.1?&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 20:59:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539833#M110749</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2023-04-23T20:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539834#M110750</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes!&amp;nbsp; That's it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't have to add new objects to the new Pano.&amp;nbsp; The "load config partial" will do that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would upgrade your old Pano and NGFWs to 10.1 so that the config is exactly the same.&amp;nbsp; Technically, Pano can manage older versions but sometimes there are errors.&amp;nbsp; Trying to make everything like-for-like reduces errors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 21:03:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539834#M110750</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-23T21:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539835#M110751</link>
      <description>&lt;P&gt;Thank you very much,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;New pano is 10.1 (panorama mode) with a mix of 10.1.x and 9.1.x NGFWs (upgrade planned for this year).&amp;nbsp; Old pano is 9.1.x (legacy mode), managing all 9.1.x NGFWs.&amp;nbsp; I think at minimum, I'll try to get that Pano to 10.1 panorama mode first, if possible.&amp;nbsp; I know that location is doesn't have much storage capacity left.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 22:13:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/539835#M110751</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2023-04-23T22:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570351#M114938</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Finally ready to test importing the old panorama config into our main panorama but can't seem to figure out how to import only the device group/template configuration.&amp;nbsp; Any pointers?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 15:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570351#M114938</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2023-12-19T15:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570356#M114941</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the link for "load config partial" again.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbLCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbLCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 15:56:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570356#M114941</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-12-19T15:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570358#M114942</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;.&amp;nbsp; I do have the link.&amp;nbsp; Sorry, I meant I'm having trouble finding the proper items to import.&amp;nbsp; When I went to &amp;lt;panorama ip&amp;gt;/api,&amp;nbsp; I'm not seeing anything for device groups and templates&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 16:08:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570358#M114942</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2023-12-19T16:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570379#M114945</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the scenarios in the link, you load the config from a file.&amp;nbsp; The XML API only shows the running-config.&amp;nbsp; You can use the API to get the generic XML Path (XPath), and change the name of the device group or template that exists in the configuration file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may need to go through the link again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 19:04:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570379#M114945</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-12-19T19:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570387#M114947</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was reviewing this article&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration/xpath-location-formats-determined-by-device-configuration#id34238ccb-2aa0-43d7-a43a-034ee6adf695" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration/xpath-location-formats-determined-by-device-configuration#id34238ccb-2aa0-43d7-a43a-034ee6adf695&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess I thought I would be able to import a partial config and pull in all the device groups and templates that I want to bring in but maybe I need to do them one at a time?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;load config partial mode merge from-xpath&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;devices/entry[@name='localhost.localdomain']/device-group/entry[@name='&lt;STRONG&gt;&amp;lt;my device group name&amp;gt;&lt;/STRONG&gt;']/&amp;nbsp; to-xpath&amp;nbsp;
&lt;DIV&gt;/config/devices/entry[@name='localhost.localdomain']/device-group/entry[@name='&lt;STRONG&gt;&amp;lt;my device group name&amp;gt;&lt;/STRONG&gt;']/ from myfilename.xml&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Then for something template, I'm guessing it would be&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;load config partial mode merge from-xpath&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;devices/entry[@name='localhost.localdomain']/template/entry[@name='&lt;STRONG&gt;&amp;lt;my template name&amp;gt;&lt;/STRONG&gt;']&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Going to open a TAC case to see if they can assist&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 20:37:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570387#M114947</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2023-12-19T20:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Move firewall to new Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570388#M114948</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Exactly.&amp;nbsp; That's what I had in mind.&amp;nbsp; I'm sorry.&amp;nbsp; How many device groups and templates do you have?&amp;nbsp; You could try the load from-xpath with just /device-group/ and /template/ without the /entry/....&amp;nbsp; That would may also merge the shared device group which may be what you want.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 20:42:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-firewall-to-new-panorama/m-p/570388#M114948</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-12-19T20:42:50Z</dc:date>
    </item>
  </channel>
</rss>

